Google Groups Home
Help | Sign in
Discussions > Random chit-chat > chmod 777 and 775 hack attempt
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  4 messages - Collapse all
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
djc  
View profile
 More options Aug 31 2007, 4:43 pm
From: djc
Date: Fri, 31 Aug 2007 13:43:10 -0700
Local: Fri, Aug 31 2007 4:43 pm
Subject: chmod 777 and 775 hack attempt
Today there are a number of attempts being reported toady that a bot
is attempting to deface sites (777 and 775 folders)

The bot will add/alter the htaccess and plant a php file where the
file names appears to be a random number.  No word yet on IPs but
chances are they will turn out to be highjacked computers or servers.

If I hear anything more, I'll let you know.  I'll be intested to see
what the php file does.


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
djc  
View profile
(1 user)  More options Aug 31 2007, 4:47 pm
From: djc
Date: Fri, 31 Aug 2007 13:47:11 -0700
Local: Fri, Aug 31 2007 4:47 pm
Subject: Re: chmod 777 and 775 hack attempt
The bot is a libwww bot....no big surprise there

On Aug 31, 3:43 pm, djc wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
webado  
View profile
 More options Aug 31 2007, 8:20 pm
From: webado
Date: Sat, 01 Sep 2007 00:20:57 -0000
Local: Fri, Aug 31 2007 8:20 pm
Subject: Re: chmod 777 and 775 hack attempt
How are they getting access? Just because a folder is chmod 777
doesn't mean you can access it from outside the website.

On Aug 31, 4:47 pm, djc wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
djc  
View profile
(1 user)  More options Sep 1 2007, 9:20 am
From: djc
Date: Sat, 01 Sep 2007 06:20:25 -0700
Local: Sat, Sep 1 2007 9:20 am
Subject: Re: chmod 777 and 775 hack attempt
Folders with "write" permissions are a gold mind for hackers
regardless of server type.

777 on a shared host with php installed can be a true mess unless the
IT took a few extra steps when installing php. open_basedir can be
used to define where scripts can write to....set correctly, I can
write to mine, but not to yours.  Many servers do not take the time to
do this.  So if you and I were on the same poorly setup server, I
could write to your 777 folder from a script that resides in mine.
Exactly how a hacker that is not on the same ever exploits this, I
have no idea but chances are 775 hacks would follow a similar
process.  Write permission on a Windows server with no php installed
is also a gold mine for hackers so it's not just a php security
issue.  I'm not sure what changed with 2003 but that has proved to be
much safer for folders with write permissions than older versions but
even then, there are so many things like an unpatched FTP server, poor
firewall, open ports, unpatched SQL, etc  than can give a hacker
access.

Much to my surprise I also got an email from an open source project
that I am using saying the same thing. They tried to pass it off as a
security hole that was fixed in an earlier version but after just
looking at a few sites this morning done with a version "just"
released, I found over 70% of those were down and only 1 of the last
version.  Luckily, I hadn't installed the new version and I do not
allow for file uploads.

I also don't think this is really a defacing hack as a 404 php is
added to make it appear as though all the pages are no longer
available and fake 404's were quite common on some hacks ~9 months or
so ago that installed some kind of garbage (for the life of me, I
forget what the virus supposed to do other than the fact on most PC's
it failed)

I've asked anyone that still has the altered files to send me copies.
As of last night, I think most thought I was the hacker and got
"NO !".  Hopefully now that I've found more sites, I can get a copy of
files from at least one but I would really love some from sites not
using this same project so I can see if they are in fact the same
thing.

On Aug 31, 7:20 pm, webado wrote:


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2008 Google